Legal
Privacy policy
Effective 29 September 2026 · Last updated 29 September 2026
This policy covers the Auto Lookup browser extension and the licence portal at autolookup.vercel.app. It says what is collected, why, where it goes, how long it is kept and how to get rid of it — written to match what the software actually does, down to the individual fields and storage keys.
On this page
1. Who we are
The service is operated by Umair Zakria, [registered address - to confirm]. For anything in this policy — including access, correction and deletion requests — write to umairzakria6@gmail.com.
This policy does not cover the websites the extension queries while it works, or your own CRM or dialer. Those are separate services under their own policies.
2. In one table
| What | Why | Where it goes |
|---|---|---|
| The phone number you look up | To run the search and show you the record | Sent from your browser to the record providers. It is not sent to this portal. |
| A name, address or phone behind a date-of-birth question | To find a date of birth for the person on the card | Used to search public-record platforms, and typed into an AI search, in your browser. |
| Your account: username, hashed password, plan, balance, last sign-in | To sign you in and meter the lookups you were issued | Stored in the portal’s database. |
| Your settings (which sources a lookup may use) | To remember your choices | Stored in your own browser, and read by the extension only. |
| The number detected on the page you are on | So you do not have to type it | Read from the page in front of you, then used exactly like a number you typed. |
| The email and message you send through the contact form | So the administrator can read it and answer you | Stored in the portal’s database and shown in its Messages view. Nothing is sent to a third party, and it is deleted when the administrator removes it or you ask for it to be removed. |
The contact form is the only place this site accepts anything from a visitor, and it stores exactly two things: the address you type and what you write. There is no newsletter, no account, no cookie and no third-party form service behind it.
3. What the extension does with data
- The number you look up never reaches this portal. The extension tells the portal only that a lookup happened, so one credit can be deducted and your balance kept correct — that request carries your session token and nothing else. The number itself is typed into the record providers’ own pages, from your browser.
- Records are shown, not collected. What the providers return is drawn on the widget in the page you are on, and kept in memory for that page only: closing the widget or the tab discards it. There is no lookup history, in the extension or on the portal.
- Date-of-birth runs use the name, address and phone from the card you clicked, and are carried out on public-record platforms and in an AI search. The last line the run reached is shown on the card while it works.
- Address completion asks the OpenStreetMap Nominatim service to normalise an address when a record only carries a partial one, and caches the answer in your browser for up to 30 days.
- Quote runs (Ride 1 / Ride 2) send the person’s name and address to an insurance site’s own quote form, from your browser, exactly as if you had typed them there.
- No telemetry. There is no analytics, no crash reporting, no advertising identifier and no tracking pixel anywhere in the extension. It makes no network request beyond the ones described here.
- It does not read your pages. The extension never reads your browsing history, never captures keystrokes outside its own fields, takes no screenshots and does not modify the page it runs on.
4. Your account on this portal
An administrator creates your account. The record holds: the username, a bcrypt hash of the password (never the password itself), the display name, the role, the plan name, how many lookups were issued, how many remain, how many have been used in total, whether the account is active, the administrator’s private notes, and the timestamps of creation, last update and last sign-in.
Signing in returns a signed token valid for 30 days. Administrators additionally receive a token for this portal, which is held in the browser’s local storage.
5. What is stored in your browser
dnc_auth_token,dnc_auth_user— your session token and the account summary shown in the widget header, so you are not asked to sign in again on every page.dnc_api_url— the portal address the extension talks to.automation_settings— the switches from the Settings & Calibration panel.widgetPosition— where you dragged the widget to.address_completion_cache— normalised addresses, cached for up to 30 days.- Short-lived run keys such as
amica_pending_quote,mercury_pending_quote,unmask_pending_lookup,thatsthem_pending_lookupandgoogle_pending_lookup— the details of a run that is in flight. They are removed when the run ends, when you cancel it, and when the extension restarts.
All of it lives in the extension’s own storage, which no website can read and which goes away when you remove the extension. Treat your browser profile like your laptop: this storage is not separately encrypted.
6. Cookies
We set no advertising or analytics cookies, and the portal’s sign-in uses a token held by your browser rather than a cookie. The record providers and insurance sites the extension visits set their own cookies while a run is in progress; those belong to those sites, and the extension clears the ones it created when the run finishes.
7. Who else processes it
We keep the number of parties involved as small as the service allows. Those that touch data are:
- Vercel Inc. — hosts this portal and serves the API over HTTPS.
- MongoDB Atlas — the managed database that holds accounts.
- Two independent record providers — the pages your browser queries with the number you looked up. The product deliberately does not name them on screen (they appear as Record 1 and Record 2). If you need them identified for your own data-protection assessment, ask us and we will do that for your account.
- Public-record platforms used for date-of-birth discovery, and anAI search provider — queried only when you press a date-of-birth button.
- Insurance quote sites — queried only when you start a Ride 1 / Ride 2 run.
- OpenStreetMap Nominatim — resolves the partial addresses that need normalising.
We do not sell personal data, we do not share it with advertising networks, and we do not use it to build profiles of anybody.
8. Legal bases and your rights
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (delivering the lookups you were issued, keeping your balance correct), legitimate interests (keeping the service secure, preventing abuse and unauthorised sharing of accounts) and legal obligation (keeping records where the law requires it).
You may ask for access to your data, its correction or deletion, a portable copy, a restriction on how it is used, or object to processing based on legitimate interests. Write to umairzakria6@gmail.com. If you are in the EEA or the UK you may also complain to your national supervisory authority. If you are in California, we do not “sell” or “share” personal information as those terms are defined by the CCPA/CPRA, and you may exercise the same access and deletion rights through the same address.
9. How long we keep it
Account data lives for as long as the account is active, and for a short period afterwards while invoices or statutory records require it, then it is deleted. Lookup counters are part of the account and go with it. Contact messages are kept until they have been answered and dealt with, and are deleted from the portal whenever you ask — the address to write to is at the bottom of this page. On the client side, settings and the address cache stay until you clear them or remove the extension; a run’s pending data is deleted as soon as the run ends.
10. Security
Passwords are stored only as bcrypt hashes, all traffic is over TLS, sessions expire after 30 days, lookups are metered per account so one account cannot be quietly shared beyond its balance, and the administrative panel is restricted by role. If you believe you have found a weakness, please tell us at umairzakria6@gmail.com before doing anything else.
11. Children
The service is a business tool. It is not directed at children, and accounts must not be created for anybody under 18.
12. Changes to this policy
When the service changes in a way that affects this policy, the policy changes with it and the date at the top of the page is updated. Material changes will be announced on this page (and, for account changes, where you sign in) before they take effect.
13. Contact
Privacy and data requests: umairzakria6@gmail.com. Everything else — accounts, lookups, bugs: umairzakria6@gmail.com.
Umair Zakria, [registered address - to confirm].
Plain-language summary: the lookup runs in your browser, the portal only counts the lookups you use, your account holds nothing but the credentials, the plan and the balance, and there is no advertising or analytics anywhere in the product.